CVE-2008-0318

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
12/02/2008
Last modified:
07/03/2011

Description

Integer overflow in the cli_scanpe function in libclamav in ClamAV before 0.92.1, as used in clamd, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Petite packed PE file, which triggers a heap-based buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:clam_anti-virus:clamav:*:*:*:*:*:*:*:* 0.92 (including)